3 ms·
If you read any topic on password managers on HN, there is very little technical discussion, its emotional and grandstanding. A majority of the comments tell pe
by FatActor 4y ago
If you read any topic on password managers on HN, there is very little technical discussion, its emotional and grandstanding. A majority of the comments tell people why their password manager sucks and your scheme is the best. It's any tech religious war basically, with more sides. But yes, that's the point: the devs start with the presumption that the blob will eventually be stolen and how to protect that. That's the initial value proposition. (Storing URLs in plaintext was dumb, but any browser extension knows every URL you visit, same with your ISP, so there's that.)
- thefurdrake 4y agoChoice of password storage and deployment seems to be an intensely-personal one that seems less attached to absolute security; it's based on how much one is really willing to trust others, how much one wants to hear about security, how exhausted one is hearing about security... and a lot of confusion because, technical-minded or not, there are a more variables than I think any one human can account for. It's stressful. I gave up on making recommendations long ago. Because of stuff like this (the latest lastpass breach), I can't in good-faith recommend cloud-based password storage, but because I know most people aren't as willing to invest a ton of time, I also can't in good-faith recommend "keepass database on cloud storage using an innocuous .png keyfile stored elsewhere that you have to wget on every new device".